fix: preserve PostgREST RPC path through DWH proxy

This commit is contained in:
User
2026-08-21 04:40:31 +02:00
parent 707c13d781
commit f616aab542
5 changed files with 11 additions and 11 deletions
@@ -382,8 +382,8 @@ Service writes only `RuntimeDirectory=dwh-auth`, reads registry, and has no secr
- [ ] **Step 5: Add Nginx templates**
HTTP map/zone rate key contains only remote address plus parsed public ID, never secret; rate is
20/s. Location uses Unix auth, `GET /verify`, no body, clears `X-API-Key` before PostgREST, burst
100, preserves `/dwh/`, maps auth infrastructure failure to 503.
20/s. Location uses Unix auth, `GET /verify`, no body, uses a trailing-slash upstream so public `/dwh/rpc/ping?x` reaches PostgREST as `/rpc/ping?x`, clears `X-API-Key` before PostgREST, burst
100, keeps the public `/dwh/` authorization boundary while stripping that prefix upstream, maps auth infrastructure failure to 503.
- [ ] **Step 6: Prove GREEN**